Back to skill

Security audit

Cooplens

Security checks for vulnerabilities and agentic risk

Overview

CoopLens is a coherent education-analysis skill that uses web research and local report generation in ways that match its stated purpose.

Before installing, understand that this skill is designed to browse current education sources and create local Markdown/HTML reports. Use it when that file and network access is acceptable, and manually verify admissions facts before making any education or financial decision.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill instructs the agent to read and write local files and fetch external sources in real time, yet no explicit permission model is declared. That mismatch creates hidden capability escalation risk: a caller or host may assume this is a low-privilege content skill when it is actually designed to access the filesystem and network extensively.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill mandates Chinese-only visible output via a fixed disclaimer and numerous output-format rules, without offering language selection. This can mislead or exclude users who cannot read Chinese, causing them to miss safety boundaries, caveats, or delivery-status information that may materially affect decisions.

Anti-Refusal Statement

High
Category
Anti-Refusal
Content
2. **计划内 vs 计划外**:计划内 usually means high-school entrance/admission through the formal志愿系统, domestic学籍 and stronger exam/employment compatibility. 计划外 requires much heavier certificate and recognition checks.
3. **证书组合与留服认证**:identify domestic graduation certificate, domestic degree, foreign degree, certificate-award conditions, whether overseas study is required, whether CSCSE/教育部留学服务中心 authentication is relevant, and what domestic credential backup exists.
4. **外方质量**:check foreign partner identity, ranking, discipline strength, real teaching input and whether the partner is only a brand label.
5. **四年总投入**:show tuition, accommodation, textbook, language, overseas phase, exchange/summer program and hidden fees. Do not judge by annual tuition only.
6. **学习压力**:English/bilingual teaching, GPA, language thresholds, retake rules, graduation delay, overseas transition and support policies.
7. **校区与资源**:campus location,住宿, library/lab access, clubs, internships, faculty sharing and whether the student is isolated from ordinary programs.
8. **转专业与调剂**:check whether cooperative majors can transfer to ordinary majors, whether high-fee programs are included in adjustment and whether major-group rules create budget risk.
Confidence
26% confidence
Finding
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Static analysis

No suspicious patterns detected.